Forum Discussion

rfroehling_7678's avatar
rfroehling_7678
Icon for Nimbostratus rankNimbostratus
Dec 18, 2008

query different LDAP Group DN

Hi,

 

 

I've a question regarding a syntax for quering an LDAP tree for users with different

 

Group DNs in a LDAP webauthentication (reverse proxy) on a Big IP virtual server.

 

 

The old apache web server configuration for this was very simple and looked like this:

 

require group ou=group1,o=member

 

require group ou=group2,o=member

 

 

In the BigIP LDAP configuration settings (Local Traffic -> Authentication Configurations) I have only the possibiliy to set on Group DN not two. Or am I wrong?

 

 

How can I search for an users in two different Group DN's

 

 

 

Regards

 

 

Ralf

 

 

  • I got the answer from F5-Support, that it isn't possible to query different Group DNs:

     

    "When you configure the LTM for a LDAP authentication, you can only configure on DN entry. That's why you have to choose the parent DN of the users groups and not try to set the users groups DNs themselves.

     

    I would also suggest you read the following document :

     

    https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm_sol_guide_943/sol_app_auth.html"